Heap-Based Buffer Overflow in Microsoft's Remote Desktop Service
CVE-2025-29966
Key Information:
- Vendor
Microsoft
- Status
- Vendor
- CVE Published:
- 13 May 2025
Badges
What is CVE-2025-29966?
The vulnerability in Microsoft's Remote Desktop Service is caused by a heap-based buffer overflow, which could allow an unauthorized attacker to execute arbitrary code over a network. This issue can be exploited by sending specially crafted requests to the Remote Desktop protocol, potentially enabling the attacker to gain control over the targeted system.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Remote Desktop client for Windows Desktop Unknown 1.2.0.0 < 1.2.6228.0
Windows 10 Version 1507 32-bit Systems 10.0.10240.0 < 10.0.10240.21014
Windows 10 Version 1607 32-bit Systems 10.0.14393.0 < 10.0.14393.8066
News Articles
References
CVSS V3.1
Timeline
- ๐พ
Exploit known to exist
- ๐ฐ
First article discovered by GBHackers News
Vulnerability published
Vulnerability Reserved